Google Play Store Launches Bug Bounty Program to Protect Popular Android Apps

Better late than never.



Google has at long last propelled a bug abundance program for Android applications on Google Play Store, welcoming security specialists to discover and report vulnerabilities in probably the most mainstream Android applications.

Named "Google Play Security Reward," the bug abundance program offers security scientists to work specifically with Android application designers to discover and settle vulnerabilities in their applications, for which Google will pay $1000 in rewards.

"The objective of the program is to additionally enhance application security which will profit designers, Android clients, and the whole Google Play biological community," the innovation mammoth says in a blog entry distributed today.

Google has teamed up with bug abundance stage, HackerOne, to oversee backend for this program, such as submitting reports and welcoming white-cap programmers and scientists.

White-cap programmers who wish to take an interest can present their discoveries straightforwardly to the application designers. Once the security helplessness has been settled, the programmer needs to present his/her bug answer to HackerOne.

Google will then pay out a reward of $1,000 in light of its Vulnerability Criteria, wherein, as indicated by the organization, more criteria might be included the future, making more degree for rewards.

"All vulnerabilities must be accounted for specifically to the application designer first. Just submit issues to the Play Security Rewards Program that have just been settled by the designer." HackerOne said.

"For the present, the extent of this program is constrained to RCE (remote-code-execution) vulnerabilities and relating POCs (Proof-of-ideas) that work on Android 4.4 gadgets and higher."

It is a lamentable truth that even after such huge numbers of endeavors by Google, vindictive applications persistently some way or another figured out how to trick its Play Store's security instrument and contaminate a large number of Android clients.

It's striking that Google Play Security Reward program does exclude finding and revealing phony, adware or malware applications accessible on Google play store, so the program won't influence the expansion in malignant applications on Google's application stage.

hackers for hire

For the present, a set number of Android applications have been added to Google Play Security Reward Program, including Alibaba, Snapchat, Duolingo, Line, Dropbox, Headspace, Mail.ru and Tinder.

So what you are sitting tight for?

Comments

Post a Comment